PT-2021-14677 · Jenkins · Jenkins Jabber (Xmpp) Notifier/Control Plugin+1

Daniel Beck

·

Published

2021-03-30

·

Updated

2023-10-25

·

CVE-2021-21634

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Jabber (XMPP) notifier and control Plugin versions 1.41 and earlier
Description The issue concerns the storage of passwords in the global configuration file on the Jenkins controller. Specifically, passwords are stored unencrypted in the file hudson.plugins.jabber.im.transport.JabberPublisher.xml, allowing users with access to the Jenkins controller file system to view them.
Recommendations For Jenkins Jabber (XMPP) notifier and control Plugin versions 1.41 and earlier, update to version 1.42 or later, as version 1.42 stores passwords encrypted once its configuration is saved again.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-21634
GHSA-79R5-RHRW-7PVH

Affected Products

Jenkins
Jenkins Jabber (Xmpp) Notifier/Control Plugin